Showing posts sorted by relevance for query skimming. Sort by date Show all posts
Showing posts sorted by relevance for query skimming. Sort by date Show all posts

Monday, November 20, 2006

ATM Skimming Case Travels to 19 Countries on 5 Continents

Skimming device (courtesy of the "ATM Pool" at Flickr)


Police in the United Kingdom are calling an ATM skimming case, one of the biggest of it's kind. ATM skimming is where a debit-card's magnetic stripe is counterfeited (cloned) and the PIN (personal identification number) is compromised - normally with a hidden camera.

Official's estimate the fraud has already netted about $4.5 million and the counterfeit cards have been used in 19 countries and five continents.

According to the story published in the SundayMirror.co.uk:

The scam was uncovered after police launched an investigation - codenamed Operation Turner - after receiving 560 complaints. Detective Sergeant Dick Bollard, who is leading the probe, said: "This is one of the biggest scams of its kind. It's a very large and complex investigation which is expected to take a considerable amount of time.

"The investigation is ongoing and we are looking into a number of leads in the UK and abroad." A spokesman for trade organisation APACS, which helps banks fight fraud, said: "These scams have involved copying a card's magnetic strip and in cases filming a driver keying in a PIN number by using some sort of hidden camera.

SundayMirror.co.uk story, here.

Two suspected dishonest employees at BP gas stations (where the devices were planted) have been arrested. One of them might be an illegal immigrant, also.

If the cards have been used in 19 countries so far, it's safe to assume that the people behind this are pretty organized. Although no one ever knows for sure, there might be Internet chatrooms (forums) - where Internet fraudsters gather to barter and sell stolen information spreading the activity.

The UK has had a lot of this skimming lately and I did a recent post about it where Romanian Illegal Immigrants were to blame.

And the UK isn't the only place that is having problems with debit-card skimming at gas stations. A similar case happened at Arco stations in California and there have been many other instances, worldwide.

BP owns Arco in the United States.

Although a lot of skimming is attributed to devices being placed on (self service) point-of-sale terminals and ATM machines, there has been recent evidence cards are also being cloned after databases have been hacked at retailers.

Some who investigate this believe that the people behind this intentionally hold on to the stolen information before using it to frustrate investigative efforts that would discover their techniques, or operations. In some recent cases, the authorities could only speculate, which of the known breaches, an individual person's information was stolen in.

Skimming can also be accomplished by retail, or restaurant employees using portable "encoding devices." Unfortunately, most of the technology used is legal and can even be bought on eBay.

It pays to keep an eye on your card to make sure it isn't being swiped more than once.

There's probably not much an individual person can do when entire databases are compromised, but an individual can shield their PIN when using their debit card (strongly recommended).

At least if they don't have your PIN, they can't get cash; however they might still be able to use the card number for signature based, or e-commerce transactions. Note that credit-cards are cloned for the same purpose.

Last, but not least - debit cards don't offer the same protection as credit cards do. If you expect to recover your money, the allowed time frame to file a claim is a lot less than with a credit card.
It's a good idea to watch your statement carefully.

If you would like a more visual demonstration of how skimming occurs, Visa has a pretty telling page (portable devices), here.

Flickr has a link to a public group pictures of ATM machines, including skimming devices, here.

There are a lot of eyes out there (customers and employees) that might spot a suspicious device - if you do - never touch it and make sure you report it to law enforcement (immediately). Since the activity normally occurs in public (retail) spaces, an educated individual could very well make the difference in cracking one of these cases. Remember that anyone near the device - no matter how official they look - might be involved, themselves.

Monday, February 20, 2006

Debit Cards Are the Criminal's Preferred Method of Payment


Hidden Camera on ATM
(above)

When the debit card breach hit the news involving Bank of America, Washington Mutual, Wells Fargo and Office Max, several stories referenced ATM skimming.

In the Northern California Breach, the card numbers were used in signature transactions versus PIN (Personal identification number) transactions. When ATM skimming is accomplished, the criminals steal not only the card number, but the PIN, also.

They are then able to use the card at any ATM.

Automatic teller machine (ATM) skimming is accomplished by attaching devices to existing ATM Machines, or via the use of hidden cameras/encoding devices in retailers that accept ATM transactions.

ATM skimming has been prevalent overseas for a few years, but is starting to show up in North America. Recently, skimming devices have been discovered on ATM machines in California, Oregon and Washington. This is why the two activities are probably being compared.

Awhile back, I did a post: ATM Machines That Clone Your Card. Included are some handy pictures of what a machine looks like after it has been compromised and tips on how to avoid becoming a victim.

There are similarities to both activities, but there are differences, also.
As I said earlier, the Northern California breach has consisted of the card numbers being used in "signature" transactions AND the victims are all from Northern California. Additionally, the authorities and Visa/Mastercard have confirmed the point of compromise as being a major retailer, reported as possibly being Office Max.
In the Northern California case, everything points to an entire database being hacked.

In the "ATM Skimming" cases, devices are being attached to existing ATM machines, which not only record the card numbers, but PIN numbers, also. The victims in the recent cases seem to span the entire West coast.

Interestingly enough, a few months ago, I did a post, which noted ATM skimming activity on the East coast:

Get a Quick $20.00 and GO BROKE!
One FBI source has already been quoted that this activity could be the work of Russian Organized Crime. Here is an interesting document from the California Attorney General, which although is slightly dated, describes how they operate.
The best way to avoid becoming a victim of ATM skimming is to always cover your PIN when entering it. We might not be able to control, whether or not, a major company is breached, but we can control our own actions when using an ATM.

Saturday, June 02, 2007

It is no wonder why skimming (credit/debit card fraud) is becoming a nasty problem!


Skimming credit and debit cards has become too easy with the irresponsible sale of technology. All the necessary techie devices to commit what many consider a "high tech crime" are being sold on the Internet - even on auction sites - such as eBay.

Yesterday, I read about an arrest of one of the Internet vendors by the Calgary Police, after they were tipped off by the United States Secret Service (USSS).

Here is what the press release from the Calgary Police Department said:
In January 2006, investigators with the U.S. Secret Service specializing in payment card fraud and Internet crime, identified a person using the Internet name of “Dron,” who was advertising skimming equipment for sale over the Internet.

A possible Calgary connection was identified and investigators assigned to the Calgary Police Service Commercial Crime Unit were involved in the investigation.

A joint, cross-border investigation was initiated. A Calgary resident was identified as the alleged manufacturer and exporter of devices which could be used for skimming data from debit and credit cards. With the assistance of other CPS units, the Calgary case has been successfully concluded.

There isn't a lot of information on how Dron was advertising his wares on the Internet, but the sad truth is he probably isn't the only vendor selling these devices.

I checked eBay (this morning) and devices that could be used to skim payment card details are being hawked (as usual) on the auction site.

In March, I wrote about a new variation (mutation) of skimming, where PIN pads were replaced at a Edmonton Wendys. The fake PIN pads are capable of transmitting card data and PIN numbers(using wireless technology) to fraudsters, who are probably sitting in a car in a parking lot.

I suspect the current fake PIN pads are being used to defeat PCI (payment card industry) data protection standards. The information is sent to the fraudster before it goes through the merchant's point of sale system.

PCI data protection standards have become a major concern lately, but it appears the criminals are already working on countermeasures that will get past them. Besides PIN pads, portable devices, used by dishonest insiders are a big problem right now, also.

Interestingly enough, even with all the media attention about PCI compliance, a large number of merchants have failed to implement them. A case to point at would be the recent TJX data breach, where at least 45 million records were compromised over a several year period.

In the Wendy's post, I identified a website called hackershomepage.com, which sells a lot of devices that can be used to commit financial crimes, including skimming. I just checked (and sadly) they are still up and open-for-business.

Of course, they publish a disclaimer on their page:
We WILL NOT answer emails from anyone asking about illegal activities, or how to use our products for illegal activities...they will automatically be deleted. All products are designed for testing and exploring the vulnerabilities of CUSTOMER-OWNED equipment, and no illegal use is encouraged or implied. We WILL NOT knowingly sell to anyone with the intent of using our products for illegal activities or uses. It is your responsibility to check the applicable laws in your city, state, and country.
This obviously is enough to keep them in business.
The PIN pad skimming variation has now been identified in both the Eastern and Western United States, as well as Canada.

Maybe if there were stricter controls on the sale of the devices that enable skimming, the problem wouldn't be so bad?

Meanwhile, expensive security technology (compliance) is being made mandatory. If history repeats itself, any technology designed (which is expensive in itself), will have a limited life span. I'm all for technological solutions, but if we don't back them up with consequences, they tend to have a limited effectiveness.

There needs to be more social solutions (laws) to bolster some of this expensive anti-fraud technology.

With millions of victims and billions of dollars being lost, I wonder why we allow this activity to be marketed over the Internet?

We are making hard working people, like USSS Agents and the Calgary Police, work pretty hard to fight a growing problem, which is victimizing a lot of PEOPLE and businesses!

Calgary Police press release, here.

Friday, June 20, 2008

Wawa gas pumps latest target of payment card skimming devices!

When I'm traveling on business in the Mid Atlantic, Wawa is a great place to stop. They literally provide just about anything a road warrior would desire.

Unfortunately their self service pumps are the latest targets of payment card (credit/debit) skimming devices. Just about any self service machine that accepts payments, or dispenses money (ATM machines) can have a skimming device mounted to it.

CBS 3 Philadephia reports:

With gas prices rising and the state of the economy in disarray, even thieves are resorting to more creative measures. At least two Wawa filling stations in the Philadelphia area have fallen victim to a string of recent credit card skimming scams.

"Just like any identity theft, until you see it on your credit card or bank statements, it's really important to check for any usual transactions," said Ela Voluck of AAA.

Thieves place a device over the card reader and can instantly record the information on the card.

Unfortunately, no pictures of the devices at Wawa seem to be available.

Recently, Redbox, a company that dispenses movies at self-service kiosks were the target of skimming devices. I have to commend them for being transparent and proactive by letting the public see exactly how this occurs.

They provided a warning on their website, along with some interesting pictures.

The only defense a person has is to carefully inspect these devices at self service places, such as the gas pumps at Wawa. Some of them are pretty bad and will literally fall off if handled too roughly.

Here are some pictures of skimming devices:








Skimmers are mounted on ATM machines, or any remote self service device. There are also portable ones that dishonest employees use to skim a card when they take it for payment.

Google has a neat sampling of pictures, which can be seen, here.

Saturday, May 20, 2006

India Seeing a Problem with Cloned Payment Cards

Skimming, cloning, counterfeiting of debit/credit cards (lately debit seems to be preferred) has been a major problem in North America and Europe. India (a new giant in the technology field) is now seeing this type of criminal activity hit home.

IBN is reporting:

One swipe is all it takes. When you hand over your credit card to make a payment in a shop or insert it into an Automated Teller Machine (ATM), you could run the risk of being the next victim of an international crime called "skimming".

And this could drain your account of all your money. Skimming is the latest fraud that has hit India hard.

The cyber crime cell of the Chennai Police recently arrested four people for withdrawing money from ATMs through forged credit cards. The police recovered 160 fake international credit cards through which they had planned to withdraw Rs 15 crore.

Link, here.

Interestingly enough, the authorities are blaming this activity as being tied into a gang from the UK, which uses a device (easily available on the Internet) known as a "skimmer."

If this activity continues to grow in India, we are likely to see "skimming devices" attached to ATM machines, likes the ones, reported in other countries.

Card skimming is growing at alarming rates, seems to be highly organized and now the evidence shows that it is becoming a global problem. It will continue to grow as long as the cards can be easily counterfeited with legal devices, which anyone can purchase.

Here is an earlier post on why technology crimes have become too easy:

Are We Addressing Cyber Crime from the Wrong End

Wednesday, June 13, 2007

San Diego Regional Fraud Task Force releases photos of suspected ATM skimmers

Devices to skim payment card information have become a big problem, whether they are portable devices used by dishonest employees at restaurants, PIN pads replaced at merchants, or devices mounted on ATM machines.

Many of the devices used recently -- use wireless technology -- and the card details are transmitted to fraudsters, normally sitting in a vehicle with a laptop.

The San Diego Regional Fraud Task Force is hot on the trail of two suspects, photographed using some of the cloned cards. Cloned cards are counterfeit devices made with the information skimmed from legitimate (credit/debit) payment cards.

Unfortunately, most of the equipment to do this, can be purchased, legally. Some of this equipment is even being sold over the Internet. Loose controls on the sale of this technology -- enables a lot of criminal activity, makes it harder for law enforcement to investigate -- and a lot of people are being victimized by it.


SignOnSanDiego.com reports:

Police are warning ATM users that scammers are using high-tech devices to steal their bank account information, including debit and credit cards numbers and personal identification codes.

Police have released photos taken from surveillance video of two suspects. Anyone with information about either man is asked to call the task force at (619) 744-2534 or the U.S. Secret Service at (619) 557-5640.

The pictures of the current people of interest in this case are featured above (to the left).

I did a post with some interesting pictures of an ATM skimming device, which are pretty educational, can be seen, here.

For other articles about payment card skimming, click here.

SignOnSanDiego.com story, here.

A lot of the skimming in the United States seems to be tied into Armenian organized crime. Glendale, which is a couple of hours North of San Diego, seems to be where a lot of this activity originates.

Maybe someone should post these pictures in the Glendale area?



Skimming device discovered at a gas (petrol) station in the United Kingdom (Courtesy of Flickr). The expression on the employee's face is worth a thousand words.

Tuesday, July 31, 2007

Customer stops debit card skimming scheme at AM/PM

Another tale of a skimming device being found at a gas station has surfaced in the local Northern California news. In this instance, a savvy customer figured out what was going on and notified the Police.

Koula Gianulias CBS 13, Sacramento reports:

Skimming at the pump. Hundreds of dollars have been stolen from unsuspecting drivers. Recently, a local driver figured out he was being taken.

When Joe Schroder tried to pay for gas at the ARCO in Newcastle, he had some trouble sliding his ATM card into the slot.

“Got up under it, pry up on this. It popped off in my hand and I knew I had something there,” says Joe Schroeder.
In June, a similar problem occurred at AM/PM stations in Huntington Beach in Southern California. One of the reasons, authorities speculate card skimmers like AM/PM is because they only accept debit cards.

As far as I've heard, the suspects in this case are still at large, also.

Huntington Beach Independent article, here.

Koula got the official statement from the parent company, which is:

”The number one priority of BP, ARCO, AM/PM is the safety and security of our customers' every transaction, every day, at all of our sites. It is unacceptable that our customers and company have been targeted by these thieves. We are continually updating our systems to further protect our customers.”

Of course, in this case, it also helps to have aware customers frequenting your premises!

CBS13 story, here.

There is an excellent video on CBS13 link, showing how one of these devices can be installed at a gas station in 20 seconds, or less!

I've also done a few posts on skimming, which might help educate people, here.

If you scroll all the way to the bottom, there are a lot of pictures and links to more pictures to take a look at.

This activity doesn't only occur in the United States. It's happening all over the world.



Similar device discovered at a gas station in Great Britain. (Courtesy of Flickr)

Story about activity in Finland, here.

Sunday, November 26, 2006

India Deals with the Problem of Credit/Debit Card Cloning


We read a lot of stories about credit/debit card skimming in the West, but see very few stories about it in other parts of the world.

India, which has become a giant in IT circles is now being victimized by the problem.

In May, I did a post about cloned credit/debit cards showing up in India. Since then I've had the pleasure of corresponding with a "security person," who is sharing information with me regarding the scope of the problem.

In November, in another case, there were more arrests in three Indian cities - 6 skimmers, laptops, a desktop and cards were seized.

The activity was facilitated with the collusion of waiters and shop-keepers.

According to my "source," more card-skimming has been uncovered and the Indian authorities are hot on it's trail. We can probably expect to see a few more criminals arrested in the not so distant future.

Until recently, cloned cards were normally sent in the mail from other destination points in Asia.

Recently, the news media was awash with stories of information being compromised at call centers in India. The industry and the government in India have quickly moved to enact legislation to counter this threat.

The stories got a lot of attention (probably because it happened in India), but in reality, information and data breaches are happening (with too much frequency), worldwide.

India seems to be proactive (refreshing) in taking legal measures, which are far more effective that technological countermeasures, to protect it's citizens and the industry, itself.

Of note, the recent skimming/cloning activity seems to have been introduced by British based gangs and the UK is suffering a "large" issue with this type of activity.

Video (interesting) on skimming in India from IBN, here.

Interesting and "informative" discussion about cyber-law in India by Praveen Dalal, here.

Monday, October 23, 2006

Romanian Illegal Immigrants Install ATM (Fraud) Machines

(Older picture of a skimming device)

Illegal immigration isn't a "victimless crime" and the work they are performing doesn't always help the economy. Apparently Romanian illegal immigrants are installing fake ATM fronts - used to steal debit-card details - for the very same criminal organizations that helped them get into the United Kingdom, illegally.

Justin Penrose of the Sunday Mirror (UK) is reporting:

They have developed a high-tech ATM front which looks exactly like the original - and it steals a victim's details in seconds.

The new cashpoint fascia is so convincing that gangs are selling it to other crooks for £10,000 a time.

The covers even have a sticker which warns customers to watch out for fraudsters. When a victim uses an ATM it records details while a camera videos the pin number. Within seconds these details are sent to a laptop and a cloned card is made. Several wealthy Romanian "godfathers" run crooked empires from their mansions in the Balkans.

Sunday Mirror story, here.

The article also states that these new and very convincing ATM fronts are being produced and sold to other criminal organizations.

I wonder how long it will be before this new "skimming device" is exported from the United Kingdom? In the past couple of years, debit-card fraud has become a worldwide problem.

This reminds me that the best defense against ATM skimming is to always cover your PIN when doing a transaction!

Here is a previous post about the growing problem of debit-card fraud:

Debit Card Breaches, A Growing Problem

And here is an older post, I did (with pictures) of a skimming device:

ATM Machines That Clone Your Card

If anyone has a picture of one of these new devices, please send it to EdwardDickson@SBCGlobal.net.

Sunday, July 31, 2005

Growing Fraud in the Mortgage Industry


In major metropolitan areas, housing prices have almost tripled. In the great rush to buy a home before it is priced beyond affordability, sharks (fraudsters) are victimizing many a person.

The FBI's Financial Crimes Report, indicates that the primary cause is an increased reliance by both financial institutions and non-financial institution lenders on third party brokers. Because of this, they have consolidated all mortgage fraud programs within their Financial Institution Fraud Unit.

A large part of the mortgage industry isn't required to report fraud, which is the reason that the true cost of mortgage fraud is hard to determine. Here are the two areas, the FBI investigates:

Fraud for Profit

"Fraud for Profit is sometimes referred to as "Industry Insider Fraud" and the motive is to revolve equity, falsely inflate the value of the property, or issue loans based on fictitious properties. Based on existing investigations and mortgage fraud reporting, 80 percent of all reported fraud losses involve collaboration or collusion by industry insiders."

Fraud for Housing

"Fraud for Housing represents illegal actions perpetrated solely by the borrower. The simple motive behind this fraud is to acquire and maintain ownership of a house under false pretenses. This type of fraud is typified by a borrower who makes misrepresentations regarding his income or employment history to qualify for a loan."

These two types of fraud are not the same as predatory lending practices, which normally affect the borrower, often a senior citizen. "Predatory lending typically effects senior citizens, lower income and challenged credit borrowers. Predatory lending forces borrowers to pay exorbitant loan origination/settlement fees, sub-prime or higher interest rates, and in some cases, unreasonable service fees. These practices often result in the borrower defaulting on his mortgage payment and undergoing foreclosure or forced refinancing."

There are a lot of other mortgage fraud schemes. The FBI primarily focuses on the above listed types, but also is trying to educate the public. "Other fraud trends include "equity skimming, property flipping, and mortgage related identity theft. Equity skimming is a tried and true method of committing mortgage fraud. Today's common equity skimming schemes involve the use of corporate shell companies, corporate identity theft, and the use or threat of bankruptcy/foreclosure to dupe homeowners and investors. Property flipping is nothing new; however, once again law enforcement is faced with an educated criminal element that is using identity theft, straw borrowers and shell companies, along with industry insiders to conceal their methods and override lender controls."

Property flipping is best described as purchasing properties and artificially inflating their value through false appraisals. The artificially valued properties are then repurchased several times for a higher price by associates of the "flipper." After three or four sham sales, the properties are foreclosed on by victim lenders. Often flipped properties are ultimately repurchased for 50 - 100 percent of their original value."

Predatory lending is primarily left to the States to investigate.

Here are some indicators and tips from the FBI on how to spot this activity and avoid becoming a victim.

MORTGAGE FRAUD INDICATORS

Inflated Appraisals

• Exclusive use of one appraiser

Increased Commissions/Bonuses - Brokers and Appraisers

• Bonuses paid (outside or at settlement) for fee-based services

• Higher than customary fees

Falsifications on Loan Applications

• Buyers told/explained how to falsify the mortgage application

• Requested to sign blank application

Fake Supporting Loan Documentation

• Requested to sign blank employee or bank forms

• Requested to sign other types of blank forms

Purchase Loans Disguised as Refinance

• Purchase loans that are disguised as refinances requires less documentation/lender scrutiny

Investors-Short Term Investments with Guaranteed Re-Purchase

• Investors used to flip property prices for fixed percentage

• Multiple "Holding Companies" utilized to increase property values

COMMON MORTGAGE FRAUD SCHEMES

Property Flipping - Property is purchased, falsely appraised at a higher value, and then quickly sold. What makes this illegal is that the appraisal information is fraudulent. The schemes typically involve one or more of the following: fraudulent appraisals, doctored loan documentation, inflating buyer income, etc. Kickbacks to buyers, investors, property/loan brokers, appraisers, title company employees are common in this scheme. A home worth $20,000 may be appraised for $80,000 or higher in this type of scheme.

Silent Second - The buyer of a property borrows the down payment from the seller through the issuance of a non-disclosed second mortgage. The primary lender believes the borrower has invested his own money in the down payment, when in fact, it is borrowed. The second mortgage may not be recorded to further conceal its status from the primary lender.

Nominee Loans/Straw Buyers - The identity of the borrower is concealed through the use of a nominee who allows the borrower to use the nominee's name and credit history to apply for a loan.

Fictitious/Stolen Identity - A fictitious/stolen identity may be used on the loan application. The applicant may be involved in an identity theft scheme: the applicant's name, personal identifying information and credit history are used without the true person's knowledge.

Inflated Appraisals - An appraiser acts in collusion with a borrower and provides a misleading appraisal report to the lender. The report inaccurately states an inflated property value.

Foreclosure Schemes - The perpetrator identifies homeowners, who are at risk of defaulting on loans or whose houses are already in foreclosure. Perpetrators mislead the homeowners into believing that they can save their homes in exchange for a transfer of the deed and up-front fees. The perpetrator profits from these schemes by remortgaging the property or pocketing fees paid by the homeowner.

Equity Skimming - An investor may use a straw buyer, false income documents, and false credit reports, to obtain a mortgage loan in the straw buyer's name. Subsequent to closing, the straw buyer signs the property over to the investor in a quit claim deed which relinquishes all rights to the property and provides no guaranty to title. The investor does not make any mortgage payments and rents the property until foreclosure takes place several months later.

Air Loans - This is a non-existent property loan where there is usually no collateral. An example of an air loan would be where a broker invents borrowers and properties, establishes accounts for payments, and maintains custodial accounts for escrows. They may set up an office with a bank of telephones, each one used as the employer, appraiser, credit agency, etc., for verification purposes.

Mortgage Fraud Prevention Measures

General Fraud Tips

Mortgage Fraud is a growing problem throughout the United States. People want to believe their homes are worth more than they are, and with housing booms going on throughout the U.S., there are people who try to capitalize on the situation and make an easy profit.

Tips to protect you from becoming a victim of Mortgage Fraud

• Get referrals for real estate and mortgage professionals. Check the licenses of the industry professionals with state, county, or city regulatory agencies.

• If it sounds too good to be true, it probably is. An outrageous promise of extraordinary profit in a short period of time signals a problem.

• Be wary of strangers and unsolicited contacts, as well as high-pressure sales techniques.

• Look at written information to include recent comparable sales in the area and other documents such as tax assessments to verify the value of the property.

• Understand what you are signing and agreeing to--If you do not understand, re-read the documents, or seek assistance from an attorney.

• Make sure the name on your application matches the name on your identification.

• Review the title history to determine if the property has been sold multiple times within a short period--It could mean that this property has been "flipped" and the value falsely inflated.

• Know and understand the terms of your mortgage--Check your information against the information in the loan documents to ensure they are accurate and complete.

• Never sign any loan documents that contain blanks--This leaves you vulnerable to fraud.•

Mortgage Debt Elimination Schemes

• Be aware of e-mails or web-based advertisements that promote the elimination of mortgage loans, credit card and other debts while requesting an up-front fee to prepare documents to satisfy the debt. The documents are typically entitled Declaration of Voidance, Bond for Discharge of Debt, Bill of Exchange, Due Bill, Redemption Certificate, or other similar variations. These documents do not achieve what they purport.

• There is no magic cure-all to relieve you of debts you incurred.

• Borrowers may end up paying thousands of dollars in fees without the elimination or reduction of any debt.

Foreclosure Fraud Schemes

Perpetrators mislead the homeowners into believing that they can save their homes in exchange for a transfer of the deed, usually in the form of a Quit-Claim Deed, and up-front fees. The perpetrator profits from these schemes by remortgaging the property or pocketing fees paid by the homeowner without preventing the foreclosure. The victim suffers the loss of the property as well as the up-front fees.

• Be aware of offers to "save" homeowners who are at risk of defaulting on loans or whose houses are already in foreclosure.

• Seek a qualified Credit Counselor or attorney to assist.

Predatory Lending Schemes

• Before purchasing a home, research information about prices of homes in the neighborhood.• Shop for a lender and compare costs. Beware of lenders who tell you that they are your only chance of getting a loan or owning your own home.

• Beware of "No Money Down" loans--This is a gimmick used to entice consumers to purchase property that they likely cannot afford or are not qualified to purchase. Be wary of mortgage professional, who falsely alter information to qualify the consumer for the loan.

• Do not let anyone convince you to borrow more money than you can afford to repay.

• Do not let anyone persuade you into making a false statement such as overstating your income, the source of your down payment, or the nature and length of your employment.• Never sign a blank document or a document containing blanks.

• Read and carefully review all loan documents signed at closing or prior to closing for accuracy, completeness and omissions.

• Be aware of cost or loan terms at closing that are not what you have agreed to.

• Do not sign anything you do not understand.

• Be suspicious if the cost of a home improvement goes up if you accept the contractor's financing.

• If it sounds too good to be true--it probably is.

An interesting blog with a wealth of information is done by Rachel Dollar, of the Dollar Law Firm. Her blog is:

www.mortgagefraudblog.com

For the full Financial Crimes Report from the FBI, which is a great resource on fraud, click on the title of this post.

Buying a home is the American dream. If you spot one of these scams, report it to your appropriate local (State) agency, or directly to the FBI at: https://tips.fbi.gov/.

Tuesday, May 09, 2006

Fraudster Gangs Deal a Blow to Chip and PIN

Picture of ATM skimming device using a hidden camera.

While North America was under attack in the Debit Card breach a few months ago, Britain rolled out Chip and PIN technology. At the time, the experts promised "Chip and PIN" cards would stop fraud dead in it's tracks.

Criminals are already beating this technology with skimming devices, which are mounted on ATM machines. AND it gets even scarier, the latest devices don't need cameras to record a PIN and can be built from parts ordered over the Internet.

Wikipedia already has an extensive section on Chip and PIN. I was amazed to discover that they were very up to date regarding potential security issues.

Chip and PIN is the name given to the initiative in the UK but countries worldwide are launching their own initiatives based on the EMV standard, which is a group effort between Europay, MasterCard and VISA. By the end of 2004, 100 countries will be using compatible systems based on this standard, and France aims to migrate its existing systems to be compatible with the new cards.

Sean Poulter of the Daily Mail reports on the recent Chip and PIN fraud:

Cloned cards belonging to Britons have been used to withdraw more than £1million in cash from machines in the UK, Paris, Sri Lanka, India and Hong Kong.

One card holder is believed to have lost as much as £25,000.

The police and banks have suggested that the problems at Shell petrol stations, which have centered on Surrey, emerged over the last eight weeks.

However, one Daily Mail reader from that area said his card details were cloned - he believes at a Shell outlet - in July last year.

Other readers believe their card details, including PINs, were stolen at garages operated by other companies, including BP and Esso. Cards have also been cloned at cash machines on at least one Total forecourt and at Tesco stores.

Full story, here.

Reading this, I had to reflect on the recent Debit Card breaches in North America. Early in the story, skimming devices were brought up a potential source. As the compromise spread across the continent, we heard rumors (still never confirmed) that retail systems were hacked. In the end, a few people were arrested and the story faded away.

Quite simply, it seems that the financial industry isn't commenting.

Whether the intention of not commenting is to protect the public, or the financial industry; it is clear that something needs to be done about this in the near term. Hopefully, the lack of information being released on these cases is because a strong investigative effort is underway.

It will be interesting to see what information is released on this latest case and how many more victims this latest caper will claim.

Here is a previous post, I did on the Debit Card breach:

Debit Card Breaches, A Growing Problem

Monday, September 19, 2005

ATM Machines That Clone Your Card

I received an e-mail showing how ATM skimming (stealing card information complete with PIN) has become more advanced with the advent of portable devices and wireless technology. Being leery of e-mail, I researched recent articles to validate this activity.

One of the articles, I researched was from NewsMax.com by Bruce Mandelblit, which can be seen, here.

Here is the text of the e-mail, I received:


"A team of organized criminals are installing equipment on legitimate bank ATM's in at least 2 regions to steal both the ATM card number and the PIN. The team sits nearby in a car receiving the information transmitted wirelessly over weekends and evenings from equipment they install on the front of the ATM (see photos).

If you see an attachment like this, do not use the ATM and report it immediately to the bank using the 800 number or phone on the front of the ATM."

The equipment used to capture your ATM card number and PIN are cleverly disguised to look like normal ATM equipment. A "skimmer" is mounted to the front of the normal ATM card slot that reads the ATM card number and transmits it to the criminals sitting in a nearby car. At the same time, a wireless camera is disguised to look like a leaflet holder and is mounted in a position to view ATM PIN entries.

The thieves copy the cards and use the PIN numbers to withdraw thousands from many accounts in a very short time directly from the bank ATM."


I also found the pictures of this on Snopes.com. Snopes is a site that reports on urban legends and whether, or not they are true. They list this one as true and based on my independent research, I believe they are right. Note that this method is being reported in Europe, South America, North America and Asia.

When going to this site, I also realized that the author of the e-mail had obtained their information from Snopes. Please note, Snopes claims to have gotten their information from the internet, also.

Snopes post, here.

This activity has been around for a few years. In the past, it was primarily done in small retailers, where the skimming device was behind the counter and the camera was over the keypad. It was also done by setting up ATM machines that were completely fake. It's always a GOOD IDEA to conceal your actions when entering your PIN. When you do this, the camera doesn't record your PIN number and they can't clone your card.

I've written a little about this phenomonen (skimming), which I update every so often. All the posts can be viewed, here.

Here is a picture of a ATM Machine after being compromised.















They attach a device over the card slot on the legitimate ATM, which reads the magnetic information. Using the latest wireless technology, it is normally transmitted to fraudsters in a nearby vehicle.
















Your ATM is protected by a PIN, but these criminals have a solution for this too. They install a hidden camera, again using the latest technology (wireless) and the PIN is digitally recorded.















Here is a picture of the compromised ATM with the camera installed.




















Saturday, April 28, 2007

While everyone sues TJX, the criminals are laughing all the way to the bank

Here is a great example of why there is so much identity theft. In Ontario, a man and his wife went right back committing identity theft, while on bail for running a payment card (debit/credit card) skimming operation. As you will see, they were by no means, small operators.

From newsregiondurham.com, Jeff Mitchell reports:

Hundreds of new charges have been laid against a fraud suspect and his wife after Durham cops busted the two as they allegedly broke his bail conditions.

Police say they found evidence of widespread fraud when they searched the King City home of the man, arrested here last fall in connection with a credit and debit card skimming operation at a north Oshawa gas bar.

One fraud investigator said lists of debit and credit card numbers found in the home amounted to "an encyclopedia" of apparently stolen data.

Here is what they got caught with, while on bail for victimizing (probably) thousands of people:

During the arrest both occupants of the car were found to have counterfeit credit cards in their possession, police said. A subsequent search of their home resulted in the seizure of credit card writing equipment, 200 phoney credit cards and hundreds of pages of credit and debit card data, police said.

Police also seized the BMW, claiming it's proceeds of crime.

I guess no one figured out the BMW was paid for by theft, the first time around?

And meanwhile, lawyers and the banking industry are organizing law suits against TJX for their recent data breach.

Unless, we start making it dangerous for the criminals to commit financial crimes, the problem will keep growing!

While a lot of people focus on civil remedies, the criminals are laughing all the way to the bank. After all, they aren't being sued. AND the sad truth is that not very many of them are being caught.

The costs of litigation and fraud are both normally passed on to the consumer. Simple economics dictates that if they were not, the business would cease to exist. The fact that the banking industry (which could also be criticized for enabling some of this problem) is behind some of this litigation, bothers me!

Someone once said, "it isn't wise to throw stones when you live in a glass house."

Maybe I should do a few posts about how the banking industry makes it too easy to commit some of these crimes? For starters, we could discuss how easy it has become to counterfeit their payment devices, which is how the information is being turned into cash (what the criminals are after). We could also discuss how little they do to verify information, when issuing a credit card and all the unsolicited offers for credit (which are routinely stolen) out of the mail.

Thinking of that, I did a post about how easily criminals can manipulate this:

Ever wonder how well you are protected from credit card fraud?

Another thing to consider is that merchants already bear a lot of the cost of fraud becaue of chargebacks. This is where the bank charges back the fraud to the merchant. Many merchants feel strongly that they are already bearing the brunt of paying for all the fraud because of this practice.

For more information on this subject, visit Merchant911.org, here.

There is no doubt that the true victims of identity theft deserve compensation, but to me some of this litigation is designed (my emphasis) to pass the buck. As I stated earlier, when the buck is passed, it gets charged to the consumer (in the end), anyway.

When is someone going to start addressing the real problem? The facts are that it's too easy to commit payment card fraud, not very many criminals are getting caught, and when they are -- the consequences are pretty minimal.

Full story from newregiondurham.com (about the crooks out committing crime on bail), here.

Sunday, April 22, 2007

Why it's become TOO easy for restaurant workers to skim payment cards

We seem to be seeing a record amount of credit/debit (payment) card fraud recently. The latest is a $3 million scheme -- where restaurant servers were recruited to steal their customer's financial information -- using portable skimming devices, which seem to be easily purchased over the Internet.

Samuel Maull of the Associated Press is reporting:

Thirteen people were indicted Friday on charges stemming from their roles in the credit card fraud, prosecutors said.

The credit card account information was stolen from customers who visited restaurants in Manhattan's Chinatown and other parts of the New York metropolitan area, as well eateries in Florida, New Hampshire, New Jersey and Connecticut.

Full AP story, courtesy of the Washington Post, here.

The Manhattan DA's site has a lot more information on this case, which reveals most of the defendants appear to have worked in Asian restaurants, were extremely organized and traveled the country buying high-end electronics.

The DA press release shows how they were turning the stolen merchandise into cash, which is the goal of most of these criminals:

THOMAS JUNG, JOON HEE KIM, JUN SHOJI, RICHARD LEE, JENG SEAK LEE, PHIL ANG, ALEX KIM and others in small groups to areas within and outside of New York State to purchase high-end electronics merchandise – such as laptop computers, Sony Play Stations, GPS navigation systems, high-end digital cameras and IPods.


PAO provided each shopper with 20 to 40 counterfeit credit cards with the expectation that each “shopper” would make fraudulent purchases in an amount that averaged $1,000 per counterfeit card. If a “shopper” was provided with 30 counterfeit credit cards, the “shopper” was expected to make $30,000 in fraudulent purchases. PAO made the travel arrangements for the “shoppers,” which included airline flights, car rentals, and hotel rooms for shopping trips in New York, New Jersey, Connecticut, Illinois, California, Oregon, Washington, Ohio,
Pennsylvania, and North Carolina.

The “shoppers,” who were paid approximately 15% of the retail value of the merchandise they bought, delivered the merchandise to PAO, who then sold the stolen goods to defendant JOHN DOE. In turn, DOE sold the goods to electronics and computer stores in Queens.

You can read the full press release, here.

Unfortunately, this problem is enabled by portable devices, which are too easy to obtain. A website, I found recently (called Hackers Homepage) seems to openly sell everything a wannabe card skimmer would need to do this. They even sell the high-quality card blanks - with the ability to place holograms on them - right over the Internet!

Of note, this site (which I hope is under surveillance) also sells more sophisticated skimming devices designed to be placed on point of sale systems, and advertises other devices and publications that would appear to enable a lot of different financial crimes.

A lot of this stuff can also be purchased on auction sites (like eBay) as demonstrated, here.

Perhaps, if we want to see a decrease in this activity, we need to enact laws that will control some of the technology, which makes it TOO easy for anyone to do.

This along with DIY (do it yourself) auction fraud and phishing kits, also being sold over the Internet, make it too easy for ANY criminal to commit pretty sophisticated crimes.

Throw in carder forums, which sell all the information being stolen, and there is no wonder why this has become a rapidly growing PROBLEM.

The bottom line is that easily purchased technology is making the problem worse, and the problem is spreading so rapidly, law enforcement has a hard time keeping up with it.

This IS NOT a victimless crime, just ask any of the people having their information stolen, or one of the businesses that have lost money from it. Of course, when businesses lose money, they have to raise prices, which means we are all paying for it.

To watch a pretty telling video on YouTube about how restaurant workers skim payment cards, link here.

Monday, November 20, 2006

Is it a Lack of Security at Retailers Causing the Debit/Credit Card Breaches?

Whether by hacking databases, or placing skimming devices on point-of-sale systems, debit/credit card fraud is raising it's ugly head, worldwide.

After finishing my most recent post about skimming devices placed on BP point-of-sale systems in the UK, I read an article in Computer World about what might be the latest large data breach.

Jaikumar Vijayan writes:


Several financial institutions last week canceled thousands of credit and debit cards in Michigan because of fraud concerns related to an apparent data compromise at a convenience store chain, highlighting the wide effect that retail security breaches can have.


Jaikumar's story, here.

Jaikumar's story states that Wesco, a retailer, is suspected as being the point-of-compromise. Of course, Wesco isn't admitting this and merely states that the matter is under investigation.

Office Max was the suspected point-of-compromise in another case last fall and to the best of my knowledge - they never admitted to being involved. Dollar Tree and Sam's Club have also recently been suspected as being points-of-compromise in breaches, where large amounts of credit/debit card information were compromised.

Why are hackers targeting retailers? The answer might be that large amounts of account information - including PINs (personal-identification-numbers) - are being maintained in databases, which are poorly protected and therefore easily compromised (hacked).

In his story, Jaikumar interviewed an expert from Gartner (Avivah Litan):


It also wasn’t clear how the data might have been breached. But four out of five data compromises involve security breaches at point-of-sale systems, said Avivah Litan, an analyst at Gartner Inc. The POS systems at convenience and grocery stores, as well as gas stations, can be especially vulnerable because of a lack of IT security awareness and resources, Litan said.

Much of the exposure results from merchants connecting their POS terminals to IP-based networks, Litan said. Often, such systems store magnetic stripe data from cards and have default passwords that can be easily hacked, she added.

The Payment Card Industry security standard explicitly prohibits the storing of magnetic stripe data on POS systems. But retailers continue to do so, and many POS applications store the data by default, Litan said.


The problem is that the retailers never admit to being breached, the banks give out limited information when asked about it, and it appears that there are too many companies not following the Payment Card Industry Data Security Standard.

Perhaps the problem is that Payment Card Industry Data Security Standard isn't being enforced and the consequences are lacking for those in violation of it. At a minumum, shouldn't these companies be prevented from doing electronic payments by the industry?

Even if a lot of the losses are being written-off, they are normally passed on to everyone in the form of increased fees, interest rates, or in the case of retailers - higher prices. Despite this, there are also people that are denied compensation, especially if they fail to be timely in filing a claim; or a PIN was used and they can't tie it into a known breach.

With the amount of data-breaches, it's often difficult to figure out where any particular person's information was stolen from.

If the Payment Card Industry can't clean up their own backyard, perhaps it's time for some government inquiries into why so much information is being compromised?

Even without government intervention, there is the matter of consumer confidence to be considered. Consumer confidence is what makes businesses thrive, and a lack of it can be a disaster for all of those involved.

I'm sure there are retailers protecting their information properly, and the ones who aren't give everyone a bad name.

Wednesday, October 25, 2006

Are RFID Credit Cards Safe?

The RFID ConsortiUm for Security and Privacy (CUSP) has issued a study about vulnerabilities in first-generation RFID-enabled credit cards.

In their blog, Ari Juels writes:

Consumers in the United States today carry some twenty million or so credit cards and debit cards equipped with RFID (Radio-Frequency IDentification) chips. RFID chips communicate transaction data over short distances via radio. They eliminate the need to swipe cards or hand them to merchants. Consumers can instead make payments simply by waving their cards—or even just their wallets—near point-of-sale terminals.

While appealing to both consumers and merchants, the convenience of RFID credit cards has a flip side. What a legitimate merchant terminal can read, a malicious scanning device can also read without a consumer’s consent or knowledge. RFID credit cards therefore call for particularly careful security design.

Blog post, here.

In a "nutshell," the study warns that current RFID credit cards are vulnerable to having the identities of the cardholder scanned from afar and the information could also be used in credit/debit card skimming.

They also state that this can be accomplished without great technical difficulty and that "slightly stronger data protections and cryptography would largely prevent the problems they discovered."

The study admits that "card skimming" is already a big problem, therefore these cards are unlikely to change anything that isn't already going on.

My question is when will we start developing technology that will protect the consumer instead of developing technology that will "probably" add to the problem?

There is an interesting demonstration posted by RFID-CUSP on YouTube about this, here.

Here is a previous post, I did on RFID:

RFID, A Necessary Evil; or an Invasion of Privacy?

Saturday, September 16, 2006

New ATM Scam

There has been a lot in the news recently about debit card breaches and ATM skimming, but here is something new. In Virginia Beach - an unknown person - reprogrammed an ATM by punching in a series of numbers - which made the machine issue four times as much money as it should.

The Police are having a hard time investigating it because it took nine days before someone reported getting more money than they should.

I wonder if all the people - who didn't report it - will have to pay the money back?

Story from AP (Associated Press), here.

Here is a previous story, I did on ATM skimming:

ATM Machines That Clone Your Card

9-22-06 (Update): Tom Fragala (Truston) did a post on how easy this was to do - AND the how to "info can be downloaded on the Internet - here.

My comment is , "ouch!"

Friday, January 06, 2006

Get a Quick $20.00 and GO BROKE!

For the last year, I've noticed an increase in "ATM Skimming." ATM Skimming was big a few years ago when criminals would plant a fake ATM Automatic teller machine (portable type) in a public place. The fake machine would electronically take your card information and a hidden camera would record your Personal identification number (PIN).

The crooks would then "copy" your card and then since the hidden camera had recorded your PIN abruptly clean out your account.

This activity seemed to disappear, then reappear (mutate) in a much more dangerous form. With wireless technology, criminals are now attaching hardware to existing ATM's at banks and doing the same thing. The difference being that you are going to your regular ATM (which you trust) and they are capturing the information from a distance.

They often do this over a weekend, or holiday, then remove the devices before anyone notices that the ATM machine has been compromised.

Recently, I've noticed reports of this activity on the rise in Europe, Asia and South America. The activity is increasing in frequency and showing up in North America, also.

Here is a post, I did several months ago, which includes photographs of the hardware and what to be on the look out for: ATM Machines That Clone Your Card. Please note that included in this post are (descriptive photographs) for the average person to learn what to be AWARE OF!

Here is one of many stories from the mainstream media on the latest scam, which hit in New York City, courtesy of the fine people at FOX News:


"A team of clever crooks ripped off more than $100,000 from at least 50 unsuspecting ATM users in Chinatown and on Staten Island in one of the largest ever info-heists from city banks, police said yesterday."

For the full story by FOX, please read, ATM Scam Nets Thieves Over $100G.

Friday, November 30, 2007

Operation Bot Roast II snares bot herders, worldwide!


Official FBI photo for Bot Roast II (Globe in a laptop)

This morning I read that a teenager in New Zealand had been arrested for allegedly being the kingpin behind an international cyber-crime network.

Because he was a juvenile when the crimes were being committed, the authorities aren't releasing his real name, but on the Internet he is known as "AKILL."

The Associated Press is reporting:

Police arrested the suspected teenage kingpin of an international cyber crime network accused of infiltrating 1.3 million computers and skimming millions of dollars from victims' bank accounts, officials said.

Working with the FBI and police in the Netherlands, New Zealand police arrested the 18-year-old in the North Island city of Hamilton, said Martin Kleintjes, head of the police electronic crime center. The suspect's name was not immediately available.

Kleintjes charged that the ring was responsible for stealing at least $20 million using bank account and login details detected by their illegal spyware.
I decided to do a little digging on this and the FBI announced on their site that this is part of Operation Bot Roast II.

It appears that more than a teenager is being taken down for victimizing millions of people, worldwide.

From the announcement on the FBI site:

In June, we announced the first phase of Operation Bot Roast, which pinpointed more than a million victimized computers and charged a number of individuals around the country with various cyber-related crimes.

Today, we’re announcing part two of this operation, with more results:

Three new indictments, including two this past month. In one case, we uncovered a denial of service attack on a major university in the Philadelphia area and then knocked out much of the botnet by disrupting its ability to talk to other computers.

Two previously charged criminals who pled guilty, including a California man who is a well known member of the botnet underground.

The sentencing of three others, including a pair of men who launched a major phishing scheme targeting a Midwest bank that led to millions of dollars in losses.
I discovered more information on Operation Bot Roast II in a FBI press release:

The FBI today announced the results of the second phase of its continuing investigation into a growing and serious problem involving criminal use of botnets. Since Operation 'Bot Roast' was announced last June, eight individuals have been indicted, pled guilty, or been sentenced for crimes related to botnet activity. Additionally, 13 search warrants were served in the U.S. and by overseas law enforcement partners in connection with this operation. This ongoing investigative effort has thus far uncovered more than $20 million in economic loss and more than one million victim computers.

FBI Director Robert S. Mueller, III said, "Today, botnets are the weapon of choice of cyber criminals. They seek to conceal their criminal activities by using third party computers as vehicles for their crimes. In Bot Roast II, we see the diverse and complex nature of crimes that are being committed through the use of botnets. Despite this enormous challenge, we will continue to be aggressive in finding those responsible for attempting to exploit unknowing Internet users."

The press release also has detail on the most current arrests:

1. Ryan Brett Goldstein, 21, of Ambler, Pennsylvania, was indicted on 11/01/07 by a federal grand jury in the Eastern District of Pennsylvania for botnet related activity which caused a distributed denial of service (DDoS) attack at a major Philadelphia area university. In the midst of this investigation the FBI was able to neutralize a vast portion of the criminal botnet by disrupting the botnet's ability to communicate with other botnets. In doing so, it reduced the risk for infected computers to facilitate further criminal activity. This investigation continues as more individuals are being sought.

2. Adam Sweaney, 27, of Tacoma, Washington, pled guilty on September 24, 2007 in U.S. District Court, District of Columbia, to a one count felony violation for conspiracy fraud and related activity in connection with computers. He conspired with others to send tens of thousands of email messages during a one-year period. In addition, Sweaney surreptitiously gained control of hundreds of thousands of bot controlled computers. Sweaney would then lease the capabilities of the compromised computers to others who launched spam and DDoS attacks.

3. Robert Matthew Bentley of Panama City, Florida, was indicted on 11/27/07 by a federal grand jury in the Northern District of Florida for his involvement in botnet related activity involving coding and adware schemes. This investigation is being conducted by the U.S. Secret Service.

4. Alexander Dmitriyevich Paskalov, 38, multiple U.S. addresses, was sentenced on 10/12/2007 in U.S. District Court, Northern District of Florida, and received 42 months in prison for his participation in a significant and complex phishing scheme that targeted a major financial institution in the Midwest and resulted in multi-million dollar losses.

5. Azizbek Takhirovich Mamadjanov, 21, residing in Florida, was sentenced in June 2007 in U.S. District Court, Northern District of Florida, to 24 months in prison for his part in the same Midwest bank phishing scheme as Paskalov. Paskalov established a bogus company and then opened accounts in the names of the bogus company. The phishing scheme in which Paskolov and Mamadjanov participated targeted other businesses and electronically transferred substantial sums of money into their bogus business accounts. Immigrations Customs Enforcement, Florida Department of Law Enforcement, and the Panama City Beach Police Department were active partners in this investigation.

6. John Schiefer, 26, of Los Angeles, California, agreed to plead guilty on 11/8/2007 in U.S. District Court in the Central District of California, to a four felony count criminal information. A well-known member of the botnet underground, Schiefer used malicious software to intercept Internet communications, steal usernames and passwords, and defraud legitimate businesses. Schiefer transferred compromised communications and usernames and passwords and also used them to fraudulently purchase goods for himself. This case was the first time in the U.S. that someone has been charged under the federal wiretap statute for conduct related to botnets.

7. Gregory King, 21, of Fairfield, California, was indicted on 9/27/2007 by a federal grand jury in the Central District of California on four counts of transmission of code to cause damage to a protected computer. King allegedly conducted DDoS attacks against various companies including a web based company designed to combat phishing and malware.

8. Jason Michael Downey, 24, of Dry Ridge, Kentucky, was sentenced on 10/23/2007 in U.S. District Court, Eastern District of Michigan, to 12 months in prison followed by probation, restitution, and community service for operating a large botnet that conducted numerous DDoS attacks that resulted in substantial damages. Downey operated Internet Relay Chat (IRC) network Rizon. Downey stated that most of the attacks he committed were on other IRC networks or on the people that operated them. Downey's targets of DDoS often resided on shared servers which contained other customer's data. As a result of DDoS to his target, innocent customers residing on the same physical server also fell victim to his attacks. One victim confirmed financial damages of $19,500 as a result of the DDoS attacks.
Recently, I did a post, Botnet owner faces 60 years in prison and a $1.75 million fine, which is about about John Schiefer (above).

The amount of damage bot herders have caused millions of people on the Internet is astounding. Even when you consider the amount of spam, the average Internet user has to deal with on a daily basis, these current arrests are good news for the Internet community. Spam is the vehicle in which most scams, misleading advertising and counterfeit goods are spread in the electronic world.

The FBI press release mentioned some great resources where the average person can learn how to avoid becoming the victim of a bot herder.

In closing, I would like to pass them on:

http://www.fbi.gov/
http://www.onguardonline.gov/
http://www.lookstoogoodtobetrue.com/
http://www.uscert.gov/
http://www.ic3.gov/

One not mentioned that is great (my opinion) is http://www.fakechecks.org/. A lot of the scams involving counterfeit checks start with a spam e-mail AND most spam is spread using botnets.

AP article on New Zealand teenage bot herder, here.

FBI press release on Bot Roast II, here.

Tuesday, March 18, 2008

Hannaford Brothers data breach might reveal current security standards are outdated

Hannaford Bros. Co., a grocery retailer based in the Eastern United States is the latest corporation to be victimized by a substantial data breach. Saying that, customers of Hannaford Bros. are going to be victimized, also. So will a lot of financial institutions, who have to deal with the fraud claims and trying to prevent the information from being used.

Whenever a data breach of this magnitude occurs, there are a lot of victims.

This breach occurred despite that fact Hannaford Bros. had met the payment card industry (PCI) standards for data protection and were not using wireless technology to transmit unencrypted data. Both of these factors were said to have caused the now infamous TJX breach, where approximately 98 million records were compromised.

This time only a reported 4.2 million records have been stolen, but it's still early in the game and historically these estimates tend to blossom with time.

A press release from Hannaford revealed that no personal information was stolen in this occurrence and that only payment card (credit/debit) card numbers are at risk.

Additionally, there have been 1800 reported cases of fraud tied into this data breach thus far.

Today, the AP was able to get a comment from their corporate headquarters:

It was during the card approval process that more than 4 million customer accounts at grocery stores in the Northeast and Florida were exposed to fraud, even though the company meets the latest standards for data security, a spokeswoman said Tuesday.

Hannaford Bros. Co. doesn't yet know how the breach — which began Dec. 7 and ended March 10 — occurred, said Carol Eleazer, vice president of marketing for Hannaford, based in Scarborough.

About 4.2 million credit and debit card numbers were exposed and at least 1,800 stolen during the seconds it takes for that information to travel to credit card companies for approval after customers swiped their cards in checkout-line machines, Eleazer said.

Brian Krebs of the Washington Post, who does the Security Fix blog quoted an industry expert, Bryan Sartin at Cybertrust as stating:

"I would say a trend we're seeing hitting a lot of retailers right now is that these organizations can be [compliant with the credit card industry security standards] and still have customer data stolen," Sartin said. "The data in transit is allowed to traverse private links and internal infrastructure without being encrypted, and the attackers are taking advantage of that."

Once these systems have been compromised, Sartin said, the attackers typically eavesdrop on the network using "sniffer" programs that can extract credit and debit card data as it moves across the wire, before it even leaves the store's network.
If the theory in Security Fix is pans out (probably will), some precedents might exist for the basic method the hackers used. The incidents, I will reference don't sound as sophisticated as what Mr. Sartin is describing, but they happened about a year ago and hacking methods tend to mature with age.

Stop and Shop was the subject of a data breach a little over a year ago. In this case, PIN pads were being replaced with "look-alike" devices that captured all the payment card details. This hardware was later removed to download all the information that had been captured when unsuspecting customers swiped their cards.

Shortly thereafter, another compromise of this type was reported in Edmonton, Canada. In this case, a blue tooth device was used to transmit the information to a waiting car in the parking lot.

The trend with PIN pad replacement continued with a smaller breach at a grocer in the San Francisco Bay area, Albertsons in April of 2007. At the time, I had the pleasure of speaking with Blanca Torres, who was doing an article on the story.

Interestingly enough, up North in Canada, where payment card skimming has increased six-fold in recent years, an announcement was made that they plan to introduce a smart card. This technology, which is known as "chip and PIN" is already in use in Great Britain and France.

The AHN story about this by Vittorio Hernandez included (what I consider) a sage comment:

But Peter Woolford of the Retail Council of Canada is wary that although the smart cards appear to be effective in reducing incidents of fraud, sinister minds may one day find a way to hack the smart chips. "Anything the human brain puts together, another human brain can take apart," Woolford pointed out.
Sadly, once this all pans out, it will likely reveal that PCI data protection standards can and will be compromised in the future. The reason, I say sad is because a lot of retailers have spent a lot of money becoming compliant.

Throw in all the finger pointing and litigation between the different parties in all these breaches and I fear we're going to be fighting a very costly battle over what is becoming a too common item in the news.

I'll sum this post up with a rant, I wrote when the TJX breach was attracting a lot of attention:

While everyone sues TJX, the criminals are laughing all the way to the bank

Press release from Hannaford about the breach, here. They list a telephone number on it, where more information can be obtained if you think you've become a statistic.